Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,325 advisories

Loading
Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations Moderate
CVE-2026-53442 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container" Moderate
CVE-2026-53440 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins exposes other users' timezone and view names to users with Overall/Read permission Moderate
CVE-2026-53439 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins: Missing permission check allows unauthorized cancellation of queue items Moderate
CVE-2026-53438 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL Moderate
CVE-2026-53437 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS Moderate
CVE-2026-64607 was published for org.apache.httpcomponents.client5:httpclient5 (Maven) Jul 31, 2026
Lueton Credited to Lueton
Apache Log4j API: Improper encoding of non-finite floating-point values during MapMessage JSON serialization Moderate
CVE-2026-49844 was published for org.apache.logging.log4j:log4j-api (Maven) Jul 11, 2026
ppkarwasz Credited to ppkarwasz, ashwani945, and Lueton ashwani945 ashwani945
Lueton Lueton
Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL Moderate
CVE-2026-53436 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion Moderate
CVE-2026-48043 was published for io.netty:netty-codec-http2 (Maven) Jun 11, 2026
Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names Moderate
CVE-2026-73508 was published for io.netty:netty-codec-dns (Maven) Jul 24, 2026
violetagg Credited to violetagg
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution Moderate
CVE-2026-53914 was published for org.jetbrains.kotlin:kotlin-gradle-plugin (Maven) Jun 26, 2026
marcelstoer Credited to marcelstoer and Lueton Lueton Lueton
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding Moderate
CVE-2026-41721 was published for org.springframework.data:spring-data-commons (Maven) Jun 10, 2026
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation Moderate
CVE-2026-41727 was published for org.springframework.kafka:spring-kafka (Maven) Jun 10, 2026
Spring Data REST potentially exposes persistence-layer internals to HTTP clients Moderate
CVE-2026-41730 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations Moderate
CVE-2026-41837 was published for org.springframework.data:spring-data-rest-core (Maven) Jun 10, 2026
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter Moderate
CVE-2026-41008 was published for org.springframework.security:spring-security-oauth2-authorization-server (Maven) Jun 10, 2026
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue Moderate
CVE-2026-41701 was published for org.springframework.amqp:spring-amqp (Maven) Jun 10, 2026
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods Moderate
CVE-2026-41696 was published for org.springframework.data:spring-data-mongodb (Maven) Jun 10, 2026
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference Moderate
CVE-2026-41697 was published for org.springframework.data:spring-data-relational (Maven) Jun 10, 2026
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache Moderate
CVE-2026-41706 was published for org.springframework.security:spring-security-web (Maven) Jun 10, 2026
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS) Moderate
CVE-2026-41711 was published for org.springframework.data:spring-data-commons (Maven) Jun 10, 2026
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean Moderate
CVE-2026-41714 was published for org.springframework.amqp:spring-amqp (Maven) Jun 10, 2026
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries Moderate
CVE-2026-41719 was published for org.springframework.data:spring-data-keyvalue (Maven) Jun 10, 2026
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference Moderate
CVE-2026-40991 was published for org.springframework.restdocs:spring-restdocs-restassured (Maven) Jun 10, 2026
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API